Stealthy Kernel‑Mode Backdoor Daxin Resurfaces in Taiwan, Paired with New Pre‑Auth Backdoor Stupig
What Happened — Symantec’s Threat‑Hunter team discovered the China‑linked kernel‑mode rootkit Backdoor.Daxin operating on a Taiwanese subsidiary of a multinational high‑tech manufacturer in May 2026. The same host also contained a previously undocumented backdoor, Backdoor.Stupig, which injects a malicious keyboard‑layout DLL into winlogon.exe to execute commands as SYSTEM from the Windows logon screen, bypassing audit logs.
Why It Matters for Compliance & Audit Readiness
- The persistence technique evades traditional log‑based detection, highlighting gaps in access‑control monitoring and audit‑trail completeness required by SOC 2 CC6.
- Long‑term, undetected compromise underscores the need for continuous control evidence collection (e.g., endpoint telemetry, privileged‑session logging) to prove that security controls are operating effectively over time.
- Mapping these advanced TTPs to your control framework helps generate defensible audit evidence and demonstrates due‑diligence in a third‑party risk program.
Who Is Affected — High‑tech manufacturing, OEM subsidiaries, and any organization running Windows workstations/servers in high‑value environments.
Recommended Actions
- Align endpoint‑monitoring and privileged‑access controls with SOC 2 CC6 requirements; enable continuous collection of logon‑session data and kernel‑level telemetry.
- Conduct a control‑mapping exercise to ensure evidence of “pre‑authentication activity detection” is captured and retained for audit review.
- Validate that third‑party risk assessments include verification of kernel‑mode driver integrity and supply‑chain provenance.
Technical Notes
- Attack vector: Kernel‑mode driver backdoor (Daxin) + pre‑auth DLL injection (Stupig).
- Persistence: Winlogon.exe DLL load, no logon audit event.
- Compile timestamps: Early 2013 (both samples).
- Detection gap: Host telemetry only reported in May 2026, suggesting up to 13 years of undetected presence.